{"api_version":"1","generated_at":"2026-07-24T20:42:10+00:00","cve":"CVE-2006-3291","urls":{"html":"https://cve.report/CVE-2006-3291","api":"https://cve.report/api/cve/CVE-2006-3291.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3291","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3291"},"summary":{"title":"CVE-2006-3291","description":"The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the \"Local User List Only (Individual Passwords)\" setting, which removes all security and password configurations and allows remote attackers to access the system.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-06-28 23:05:00","updated_at":"2017-07-20 01:32:00"},"problem_types":["CWE-16"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27437","name":"cisco-ap-browser-unauth-access(27437)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/26878","name":"26878","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/18704","name":"18704","refsource":"BID","tags":[],"title":"Cisco Access Point Web Interface Authorization Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/2584","name":"ADV-2006-2584","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016399","name":"1016399","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Cisco Access Point Configuration Error May Let Remote Users Gain Administrative Access","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20860","name":"20860","refsource":"SECUNIA","tags":[],"title":"Cisco Wireless Access Point Web Management Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/544484","name":"VU#544484","refsource":"CERT-VN","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#544484","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisco.com/warp/public/707/cisco-sa-20060628-ap.shtml","name":"20060628 Access Point Web-browser Interface Vulnerability","refsource":"CISCO","tags":["Patch"],"title":"Cisco - Networking, Cloud, and Cybersecurity Solutions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3291","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3291","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3291","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.3(8)ja","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3291","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.3(8)ja1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3291","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.3\\(8\\)ja","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3291","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.3\\(8\\)ja1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3291","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.3\\(8\\)ja","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3291","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"12.3\\(8\\)ja1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3291","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the \"Local User List Only (Individual Passwords)\" setting, which removes all security and password configurations and allows remote attackers to access the system."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"18704","refsource":"BID","url":"http://www.securityfocus.com/bid/18704"},{"name":"cisco-ap-browser-unauth-access(27437)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27437"},{"name":"20060628 Access Point Web-browser Interface Vulnerability","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/cisco-sa-20060628-ap.shtml"},{"name":"26878","refsource":"OSVDB","url":"http://www.osvdb.org/26878"},{"name":"1016399","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016399"},{"name":"ADV-2006-2584","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2584"},{"name":"VU#544484","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/544484"},{"name":"20860","refsource":"SECUNIA","url":"http://secunia.com/advisories/20860"}]}},"nvd":{"publishedDate":"2006-06-28 23:05:00","lastModifiedDate":"2017-07-20 01:32:00","problem_types":["CWE-16"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:ios:12.3\\(8\\)ja1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:ios:12.3\\(8\\)ja:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3291","Ordinal":"18616","Title":"CVE-2006-3291","CVE":"CVE-2006-3291","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3291","Ordinal":"1","NoteData":"The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the \"Local User List Only (Individual Passwords)\" setting, which removes all security and password configurations and allows remote attackers to access the system.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3291","Ordinal":"2","NoteData":"2006-06-28","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3291","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}